A forum user named Jurak is offering what they claim is a 77 Diamonds customer database containing home addresses, phone numbers, wedding dates, and appointment budgets. The alleged file also includes administrator records and payment gateway webhook events, but the breach claim remains unverified. #77Diamonds #Jurak…
Category: Cyber Attack
BHIS ActiveSOC investigated an Aur0ra ransomware intrusion that began with vishing after aggressive email bombing, then escalated into custom C2 activity and noisy lateral movement. The attackers used Xray-core disguised as ChromeUpdate.exe and ConnectivityHost.exe, while the locker encrypted files in place and dropped the !!!README!!!DO_NOT_DELETE.txt ransom note. #Aur0ra #Xray-core #ChromeUpdate.exe #ConnectivityHost.exe #README_DO_NOT_DELETE.txt
Boston Scientific disclosed a cybersecurity incident affecting certain computer systems and causing operational disruptions, including limitations on access to key information systems and business applications. The company has brought in external experts to assess and contain the threat, while the full scope and recovery timeline remain unclear. #BostonScientific
Paylogix, a U.S.-based employee benefits management platform, said hackers stole sensitive personal data including Social Security numbers, financial details, health information, and passport numbers. The attack occurred between November 13 and November 18 and was later claimed by the Akira ransomware group in January 2026. #Paylogix #Akira
A forum user named GordonFreeman is advertising what is claimed to be the complete Chilean electoral roll from SERVEL, covering 13,737,519 citizens in a 3.35 GB .DB file. The post is unverified, includes a 500,000-record sample, and exposes sensitive fields such as RUT, addresses, and polling-place details. #SERVEL #GordonFreeman #Chile…
A forum user named sh444d0w claims to have shared Agence Vauban database data for free, including 5,430 user accounts and detailed property-related records. The post is unverified, but it appears structurally convincing and could expose sensitive client, financial, and property information. #AgenceVauban #sh444d0w…
A forum user calling themselves GordonFreeman claims to have breached the Junta Central Electoral and advertised 7,141,313 Dominican citizen records with 5,758,124 identity card photographs. The alleged dump includes cédula numbers, personal details, and JPEG portraits, but the claim remains unverified and no price was stated. #JuntaCentralElectoral #GordonFreeman #DominicanRepublic…
A forum user known as 0xSec claims to have published three XLSX user tables from docurba.beta.gouv.fr, exposing 5,152 rows of French planning officials’ names, contact details, job titles, and authority data. The alleged leak also includes administrator and staff flags, verification status, and login indicators, but the claim remains unverified. #docurba.beta.gouv.fr…
A forum user posting as 0xSec claimed to share the database of metabase.dipeeo.fr, a French GDPR compliance provider serving organisations with outsourced Data Protection Officer services and compliance software. The release reportedly contains eleven JSON collections with client, legal officer, user, subcontractor, and processing records, but the claim remains unverified and…
A forum actor posting as 888 is offering what they claim is the MyNewTerm database in a one-time Monero sale, with the alleged breach said to expose 142,653 unique users. The reported data includes applicant email addresses, job application outcomes, recruiter notes, and vacancy details tied to UK education recruitment. #MyNewTerm…
Franklin Mint Federal Credit Union (FMFCU) experienced a website and digital banking outage after a domain issue disrupted access to its online services. The credit union said transactions continued to process and did not describe the incident as a cyberattack. #FranklinMintFederalCreditUnion #FMFCU #GoDaddy #fmfcuorg
IServ, the national school platform in Germany, was hit by a cyberattack affecting a cloud module operated by the provider. Hattingen officials said local schools use the module and may be indirectly affected, but no personal data breach involving students or parents has been confirmed so far. #IServ #Hattingen
The municipal government of San Luis Potosí was hit by a ransomware attack in which the attackers demanded payment in exchange for not releasing stolen information. The city refused to negotiate, filed a federal complaint, and confirmed that while much of the exposed data was already public, its systems were still compromised. #SanLuisPotosí #sanluisgobmx
Sotheby’s International is investigating a cybersecurity incident involving unauthorized access to data stored on a third-party software platform. Potentially exposed information includes names, addresses, email addresses, and phone numbers, while email exchanges, property-related documentation, and financial transaction data were not accessed. #SothebysInternational #Sothebys.com
Researchers found over 28,000 publicly exposed Git repositories across 3.5 million active web servers, revealing live AWS keys, Stripe secrets, GitHub tokens, and sensitive internal records. The exposure was caused by misconfigured public .git directories, putting organizations at risk of cloud takeover, financial data theft, and access to internal systems. #IntruderResearch…